Using access control for secure information flow in a Java-like language

Using access control for secure information flow in a Java-like language
复制标题

使用类 Java 语言中的安全信息流的访问控制

DOI:
10.1109/csfw.2003.1212711
复制
发表时间:
2003
期刊:
16th IEEE Computer Security Foundations Workshop, 2003. Proceedings.
影响因子:
--
通讯作者:
D. Naumann
D. Naumann
中科院分区:
--
文献类型:
--
作者:
A. Banerjee;D. Naumann

文献摘要

被引文献

相似文献

访问控制机制被广泛使用,目的是执行机密性和其他策略,但信息流和访问控制之间几乎没有建立正式的联系。 Java 和 C# 是提供细粒度访问控制的面向对象语言。访问控制列表通过为与类声明关联的主体(代码源)授予权限来指定本地策略;称为堆栈检查的机制在运行时检查权限。给出了一个例子来说明在单个系统调用为不同机密级别的调用者提供服务并且动态访问控制防止向低调用者发布高信息的情况下,如何使用该机制来实现机密性目标。给出了适用于此类示例的静态分析。该分析表明可以确保形式化机密性的无干扰属性。
Access control mechanisms are widely used with the intent of enforcing confidentiality and other policies, but few formal connections have been made between information flow and access control. Java and C# are object-oriented languages that provide fine-grained access control. An access control list specifies local policy by authorizing permissions for principals (code sources) associated with class declarations; a mechanism called stack inspection checks permissions at run time. An example is given to show how this mechanism can be used to achieve confidentiality goals in situations where a single system call serves callers of differing confidentiality levels and dynamic access control prevents release of high information to low callers. A static analysis is given which applies to such examples. The analysis is shown to ensure a noninterference property formalizing confidentiality.